First-Layer UI
The First-Layer UI is the initial cookie consent notice a user sees when they first arrive on a website, typically shown as a banner or overlay. It gives a short summary of how the site uses cookies and similar technologies and presents the main choices, such as accepting or rejecting non-essential cookies. More detailed information and granular controls are usually available on a second layer that the user can open from this first screen.
In consent management design, the First-Layer UI refers to the top-level, immediately visible consent notice presented before or at the point of setting or accessing non-essential cookies and equivalent technologies (such as pixels, local storage, SDKs, and fingerprinting). Under EU and UK rules derived from the ePrivacy Directive as implemented nationally, the first layer generally must provide the information needed for consent to be informed and typically offers primary controls (for example, accept, reject, and access to further options) so that consent can be freely given, specific, informed, and unambiguous through a clear affirmative action. Design practices such as pre-ticked boxes, reliance on continued browsing as implied consent, and asymmetric button prominence are widely regarded by EU data protection authorities as inconsistent with valid consent, though specific expectations vary by jurisdiction and evolve with regulatory guidance. Requirements differ under US state privacy frameworks (for example the CCPA/CPRA in California), which generally rely on opt-out mechanisms and signals such as Global Privacy Control rather than prior opt-in, so first-layer design obligations are not uniform across regimes.
Why it matters
The first-layer UI is the point at which most users make their consent decision, so its design directly affects whether consent obtained on a website can be considered valid. Under EU and UK rules derived from the ePrivacy Directive as implemented nationally, consent for non-essential cookies and equivalent technologies generally must be freely given, specific, informed, and unambiguous, expressed through a clear affirmative action. Because the first layer is what the user actually sees and interacts with, it carries much of the burden of meeting the 'informed' element and of ensuring that the choice presented is genuine rather than steered.
Design choices at this layer are a recurring focus of regulatory scrutiny. Practices such as pre-ticked boxes, treating continued browsing as implied consent, and giving 'accept' far greater prominence than 'reject' are widely regarded by EU data protection authorities as inconsistent with valid consent. These are commonly described as 'dark patterns' or deceptive design, and they can undermine the lawfulness of the entire consent chain even where a consent management platform records the interaction correctly. Because the first layer typically precedes any granular second-layer controls, weaknesses here are difficult to cure downstream.
The significance of the first-layer UI is not uniform across jurisdictions. US state privacy frameworks such as the CCPA/CPRA in California generally rely on opt-out mechanisms and signals like Global Privacy Control rather than prior opt-in, so the role and required content of a first-layer interface differ from EU expectations. Organizations operating across regimes therefore cannot assume that a single banner design satisfies every applicable regime, and specific expectations continue to evolve with regulatory guidance.
Who it's relevant to
Inside First-Layer UI
Common questions
Answers to the questions practitioners most commonly ask about First-Layer UI.

